Roles & permissions

Six roles. Every capability, spelled out.

Access is least-privilege by design — each role has an explicit voice in signing and governance, enforced by the coordinator, not just hidden in the UI. A dot means the role holds a signing share.

Owner
Full authority over the wallet. Holds a share and signs, initiates transfers, proposes governance, and votes. Can remove any member except another owner.
signsinitiatesapproves
Admin
Full operational authority. Holds a share and signs, initiates transfers, proposes governance, and votes. Can remove signers, approvers and viewers — but not owners or other admins.
signsinitiatesapproves
Editor
Governance staff. Initiates transfers, proposes rule and member changes, and votes — but holds no share, so it never signs the ceremony. Can remove signers, approvers and viewers.
no shareinitiatesapproves
Signer
Holds a share and signs the MPC ceremony — nothing more. Doesn't initiate transfers, propose governance, or cast approval votes.
signsno vote
Approver
Votes on tasks other members initiate. Holds no share and can't start a transfer or a governance change — an approval voice only.
no shareapproves
Viewer
Read-only. Sees wallet state, balances and activity, but can't initiate, approve or sign anything.
read-only
RoleInitiate transferPropose governanceApprove / voteHold share & signRemove members
Owner Anyone except another owner
Admin Signer, approver, viewer
Editor Signer, approver, viewer
Signer
Approver
Viewer

“Propose governance” covers transfer- and governance-policy edits, adding or revoking members, team/group changes, whitelist edits and the wallet label. Every proposal still collects the approvals your policy requires before it takes effect — a role’s permission to start an action is separate from the quorum that must approve it.

Give everyone exactly the voice they need.

Assign roles per wallet, bundle members into approval groups, and let policy decide the rest.